The Cyberattacks on the U.S Water Sector and the Iran Question: Escalation or Opportunism?

A recent spate of cyberattacks against the United States’ water sector has impacted at least 12 states and 100 municipalities, suggesting a coordinated campaign at scale against U.S. critical infrastructure. Although unconfirmed by the U.S. government, signs point to Iran as the likely culprit. Some media outlets are even going so far as to label this an “escalation,” in directly attacking the U.S. homeland during a time of war.

Indeed, the CyberAv3ngers—a hacktivist group believed to be linked to the Islamic Revolutionary Guard Corps—has claimed responsibility for the attacks. This is typical for the Iranian playbook; its actors amplify their attacks via news and social media to maximize impact, even where the impact may be false or exaggerated.

Additionally, cyber actors tend to form behavioral signatures in cyberspace—patterns in how they target, operate, and have impact—and all signs point to Iran as the likely culprit. Iran has a deep history of conducting cyberattacks against the water section in Israel and the United States. As part of its decades-long conflict with Israel, this includes cyberattacks attempting to poison the water supply by increasing chlorine levels in in April 2020, targeting agricultural water pumps in July 2020, and Israeli water systems in 2023. It also includes cyberattacks against U.S. water systems and other critical infrastructure sectors in April 2026; Cal Water in June 2026; Pennsylvania in 2023; and New York in 2013. Moreover, the targeting of programmable logic controllers (PLCs) in the current cyberattacks (the technical components required to control industrial systems) is another giveaway; most of the incidents above are attributed by either the U.S. government or industry reporting to the CyberAv3ngers. But should the U.S. public be scared, as some outlets have suggested?

The answer is not yet. Psychological effect is precisely the point of Iran’s cyber operations, to sow fear, chaos, and division, as part of its information warfare strategy. If these attacks are indeed Iran’s doing, this commentary asserts four reasons the water incidents do not constitute escalation in this conflict; they should be regarded as opportunistic disruption owing to weak U.S. cyber defenses, rather than a turning point.

  1. In Conflict, Attackers Favour Opportunism

The cyberattacks against the U.S. water sector were not strategic, well planned, or sophisticated. From a technical perspective, they demonstrate the cyber actors exploiting extremely weak cyber defenses (e.g., default passwords, operational technology connected to the internet, and lack of authentication) using basic technical accesses.

The incidents fit a much longer-term pattern of how Iranian cyber actors behave in conflict. The attacks are not pre-positioning (i.e., gaining technical access in strategic locations ahead of time for later or subsequent use), as Iranian actors had already pre-positioning to conduct these attacks, leveraging technical accesses that go as far back as January 2025. Rather, they should be considered opportunistic disruption (also labelled “opportunistic targeting” by the U.S. government). The precedent was set in the Russia-Ukraine conflict, where Russian cyber actors would reuse the same destructive malware for different targets in order to maintain an extraordinarily high operational tempo. Iran is doing the same: exploiting low-hanging fruit through quick-and-easy cyber operations that better meet the timescales of conflict, as opposed to exquisite, tailored capabilities that can take years to develop.

For this same reason, Iran has not limited itself to attacking the U.S. water sector, but a range of U.S. critical infrastructure sectors since February, including local government (St. Joseph’s County, Indiana), energy (PLCs in energy infrastructure and fuel storage tanks in U.S. gas stations), and transport (Los Angeles metro), among others. The randomness of targeting is designed to sow insecurity and panic among the U.S. public.

  1. The Iranian Regime is Fractured

The Iranian regime is fragmented politically, and its communications infrastructure degraded from the course of the war. This means that its leadership likely lacks the means of communicatively effectively across the Iranian state apparatus—compounded by the decentralized approach that Iran shifted to in response to the United States’ decapitation campaign to remove its top leaders. It therefore highly unclear—and possibly unlikely—as to whether the cyberattacks on the water facilities were ordered by Iranian leadership; it could be the work of middle ranking operators, or even one side of the Iranian apparatus seeking to actively undermine another side by conducting an attack against the U.S. homeland to disrupt already fragile negotiations.

  1. The Intended Impact Is Psychological, Not Escalatory

Iran’s military and cyber posture has evolved to meet the needs of this war. This has meant that Iran uses its chokehold over the Strait of Hormuz as its primary form of leverage and escalating, with cyber as more of an enabling capability. Critically, this includes using cyber operations to shape the information environment to Iran’s advantage. Iranian military doctrine prioritizes the information domain as a key battlespace, meaning Iran will actively seek and foment incidents that it can leverage for cognitive effect. Though the primary goal is disruption—such as of water supply—the secondary goal of psychological impact is key. Through disrupting critical infrastructure in the United States, Iran can sow fear and a sense of insecurity, projecting its power into the U.S. homeland, far beyond its own borders.

This is where opportunistic disruption plays a critical role in information warfare goals. Iranian cyber actors quickly throw malware at poorly-defended victims—usually of symbolic value—to see what sticks, and using the resulting media coverage (whether Iranian, America, or international) to amplify their impact, enabling immediate and persistent power projection overseas. The CyberAv3ngers statement on the attacks indicates as much: Claiming their intention was to warn the United States to back down, and in retaliation for attacks on Iranian infrastructure and Minab, the use of cyberattacks indicates signaling, or projecting power to the U.S. government and citizens.

  1. Escalation Is Ultimately a Political Decision

Although attributing cyberattacks is a technical process, their final sign-off is ultimately a political decision. Various technical agencies will pull together carefully considered intelligence and evidence to determine the actor responsible, their technical modus operandi, and their attack intent, which is then passed to a senior-most decisionmaker (usually the secretary of state, or the president) to sign off.

The same principle applies to escalation, but collides with political considerations. It was highly concerning that President Trump was so quick to blame Democratic officials in Minnesota for the attacks, which was immediately refuted by Governor Tim Walz. However, Trump’s actions were also revealing in themselves, and may have reflected a deliberate calculation: minimizing conjecture as to who the perpetrators were, and quashing any space for the attacks to be perceived as escalation, in order to preserve the broader strategic space for diplomatic negotiations with Iran to continue uninterrupted.

Conclusion

Attributing technical incidents takes time—often weeks, if not months, of verification and gaining consensus across technical agencies. Nonetheless, there are some important takeaways from these concurrent incidents. The first is the importance of response. Defensively, Minnesota and other affected states should be praised for their cyber resilience actions; they were extremely quick to turn to manual overrides and backup water capacity, which prevented severe impact occurring, such as flooding or contamination of water supplies. These resilience measures also dampened Iran’s ability to exaggerate the attacks’ impact. Although President Trump downplayed these incidents rhetorically, given the aggressive posture set out in the U.S. National Cyber Strategy 2026, it is highly likely that this administration will respond privately, and we can expect the United States to mount offensive cyber operations against Iran in response.

The second takeaway is that the real value of cyber operations is often in the secondary impact they cause, in this case, for cognitive effect. Through opportunistically targeting U.S. critical infrastructure, Iran’s cyber actors are able to signal and project power far beyond their actual means. By jumping to label these attacks as escalation where they might not be is to play directly into Iran’s hands by letting fear take hold and doing its amplification work. This makes a hardened security posture—and strong cyber defenses—all the more critical against adversaries such as Iran.

Nikita Shah is a senior fellow with the Intelligence, National Security, and Technology program at the Center for Strategic and International Studies (CSIS) in Washington, D.C.

Senior Fellow, Intelligence, National Security, and Technology Program